> Source: [sk55244](https://support.checkpoint.com/results/sk/sk55244)

# sk55244 - Traffic over VPN tunnel does not pass for several seconds during policy installation on Security Gateway (which causes traffic loss)

| Property | Value |
|----------|-------|
| Solution ID | sk55244 |
| Date Created | 2010-10-07 |
| Last Modified | 2021-04-19 |
| Technical Level | Advanced |

## Symptoms

- * Traffic over VPN tunnel does not pass for several seconds during or after policy installation on Security Gateway (which causes traffic loss).

* Kernel debug ('`fw ctl debug -m fw + drop`') shows:  

  `... dropped by vpn_encrypt_chain Reason: encrypt drop;`

* Security Gateway with SAM card might enter a kernel panic (crash) in the following scenario:

  1. traffic is currently passing over VPN tunnel (encrypted UDP load)
  2. Security Gateway is rebooted
  3. instead of rebooting, Security Gateway enters a kernel panic

## Cause

1. VPN Link Selection is being reset during policy installation. This causes timeouts until VPN peers can be resolved again.

   Note: In some cases, certain VPN peers can take longer to re-establish, which would result in similar losses up to several minutes after policy push. (ID 02338534)
2. SAM card might crash in certain scenario while processing VPN traffic (related to the above cause). (ID 02277594)

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
